Darktrace AI’s Antigena helps stop ransomware attack at Dordogne GHT
Ryuk had previously overthrown city councils and attacked over 200 US hospitals in 2021
French hospital group Dordogne Groupements Hospitaliers de Territoire (Dordogne GHT) has successfully contained and stopped a ransomware attack utilizing Darktrace AI’s autonomous response technology Antigena.
In 2021, Dordogne GHT installed Darktrace's artificial intelligence (AI)-based detect, respond technologies to guard against threats in all 11 of its hospitals, particularly for medical and corporate devices pertaining to accident and emergency departments.
The system was soon put to test when Dordogne GHT encountered a notorious ransomware strain called Ryuk, which targets critical public sectors organizations worldwide.
Russian cybercriminal group Wizard Spider has been attributed to creating the ransomware. Ryuk essentially combines advanced encryption techniques before requesting a high ransom for a private decryption key. Ryuk is also one of the first ransomware strains to encrypt network drives and resources.
Darktrace AI was alerted to the first signs of the attack via some basic .dat files being downloaded onto one of the hospital’s devices through an unknown IP address. Using AI, Darktrace’s Antigena thwarted the breach, saving medical devices from being corrupted.
"At a time when national cybersecurity agencies are urging organizations to be hyper-vigilant and lock down their systems, we can be in little doubt that defenders of healthcare systems will be working to keep the bad guys out," commented Justin Fier, VP of tactical risk and response at Darktrace.
"Autonomous response technology that uplifts human security teams by allowing them to make strategic decisions while the AI stops the attack before it causes disruption is critical in defending organizations vital to everyday life," added Fier.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
2026 in IoT attacks: the biggest threats so far and what businesses can doIn-depth Internet of Things devices are more useful than ever – but security is still playing catch-up
-
Anthropic is increasing Claude Code usage limits — here’s everything you need to knowNews The new deal will help Anthropic increase Claude Code usage limits, and API rate limits for Claude Opus models
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti
-
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitationNews A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation
-
Security leaders overconfident about ransomware recoveryNews Few manage to recover all their data, and many experience business disruption
-
German authorities want your help finding the hackers behind GandCrab and REvilNews Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes
-
The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in lifeNews With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheap – but it could be their undoingNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites